Remote Cross Site Scripting Vulnerability in HPE Integrated Lights-Out
CVE-2019-11982

8.3HIGH

Key Information:

Vendor
HP
Vendor
CVE Published:
5 June 2019

Summary

A remote cross site scripting vulnerability has been discovered in HPE Integrated Lights-Out systems. This issue affects iLO 4 versions prior to 2.61b and iLO 5 versions before 1.39, allowing attackers to execute malicious scripts in the context of a user’s session, posing significant risks for session hijacking and unauthorized actions. It is crucial for users to apply security updates to mitigate potential threats and protect their systems.

Affected Version(s)

HPE iLO4 and HPE iLO5 iLO4 prior to v2.61b and iLO5 prior to v1.39

References

CVSS V3.1

Score:
8.3
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.